CuraSec

tag: Zyxel · 2 items

2026-09-22 · The Hacker News · source ↗ #cisa-kev#zyxel#veeam
  • Engineer — Act: CVE-2026-7273 is CISA KEV-listed with a public PoC on GitHub; patch Zyxel GS1900 series switch firmware immediately and audit Veeam deployments for associated flaws granting SYSTEM-level access.
  • SOC/IR — Act: Active exploitation of an edge network device warrants an assume-breach posture; sweep for Zyxel GS1900 switches in the estate and hunt for anomalous lateral movement or command execution sourced from switch management interfaces since the disclosure date.
  • Leader — Plan: CISA KEV confirmation of active exploitation in network switches and backup software (Veeam) is a concrete risk item; confirm with engineering this week that Zyxel GS1900 and Veeam instances in your environment are patched and request a status update before month-end.
  • Signals: CVE-2026-7273 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
2026-09-22 · BleepingComputer · source ↗ #cisa-kev#zyxel#network-infrastructure
  • Engineer — Act: CISA KEV listing confirms active exploitation of Zyxel GS1900 series switches; if any are in your environment, patch immediately and audit management-plane access logs for signs of unauthorized access.
  • SOC/IR — Act: Active exploitation for data theft means assume-compromise posture on any Zyxel GS1900 devices; hunt for anomalous traffic or config changes originating from or through these switches since KEV listing date.
  • Leader — Plan: Confirm whether Zyxel GS1900 switches appear in network inventory and verify patching is prioritized this week; federal agencies face a hard CISA deadline, but private-sector organizations should treat this as elevated-urgency given confirmed exploitation.